Threat Description

Z-90

Details

Aliases:Z-90
Category:Malware
Type:Virus
Platform:W32

Summary



Z-90 activates in July and December if an infected file is executed and the time is exactly 09:03. At this time the virus encrypts the DOS boot sector of drive C:, making the PC unbootable (encryption is done by XORing with 16-bit hex value 0903). After this it displays this message:

VIRUS Z-90. JUNIO 95. M
  EXICOSE MURIO TU DISCO
  DUROTU LO PUEDES RE
  VIVIRHAS BAILADO ALGUNA VEZ CON TU NOVIA A LE TENUE LUZ DE LA
		

Z-90 was found in the wild in Brazil in April 1996.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.








Description Created: Peter Szor, F-Secure, 1996


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More